IRS Publication 1075
IRS Pub 1075 Section 9.1-9.2 FTI Specific

IRS Publication 1075 IRSPub1075-Section91-92-FTI-Specific-Recordkeeping-Disclosure-Transmission-Restriction-MinSafeguards: IRS Publication 1075 Sections 9.1-9.2 + FTI-Specific Requirements + Recordkeeping + Disclosure Restrictions + Transmission Requirements + Minimum Protection Standards + Printing + Inventory + Destruction

Sections 9.1-9.2 of IRS Publication 1075 establish FTI-specific requirements that are NOT covered by NIST SP 800-53 but are specific to the IRS FTI protection regime. Section 9.1 Recordkeeping Requirements: maintain detailed records of FTI receipt + processing + disclosure + destruction + including (a) FTI Inventory + Custody Log + Receipt + Tracking; (b) Disclosure Accounting per 6103 + log of every authorised disclosure with date + recipient + purpose + statutory basis; (c) Audit Trail of all access to FTI systems + including Identifier + Timestamp + Action + Data Element; (d) Records retention per IRS Records Control Schedule (RCS) + minimum 5 years for FTI access logs + longer for safeguard records. Section 9.2 Disclosure Restrictions and Re-Disclosure: FTI may be disclosed ONLY in accordance with IRC 6103 + including (a) only to authorised personnel with bona fide need to know; (b) only for the authorised purpose; (c) no re-disclosure except as expressly authorised by statute (some inter-agency sharing allowed under 6103 with reciprocal safeguards); (d) confidentiality penalties per IRC 7213 (criminal up to 5 years imprisonment + $5000 fine per offence) + IRC 7213A (unauthorised inspection penalties) + IRC 7431 (civil damages including punitive). FTI Transmission Requirements: encryption FIPS 140-3 validated cryptographic modules + TLS 1.2 minimum (TLS 1.3 preferred) + SFTP/FTPS over plain FTP + S/MIME for email + no FTI via personal email or consumer cloud services. FTI Printing + Document Control (per Exhibit 1 + Section 9.4): print server controls + watermarking + cover sheets + Document Control Officer + paper FTI inventory + secure destruction (cross-cut shredders meeting NIST SP 800-88 + DIN 66399 P-4 or higher + DoD 5220.22-M + degaussing for electronic media + chemical pulping for paper). FTI Commingling Identification: FTI must be identifiable + marked + segregable from non-FTI data + commingling acceptable but requires marking + log + isolation upon request. Exhibit 4 Offshore Prohibition: FTI processing prohibited offshore (outside US + including Puerto Rico/Guam/territories) + cloud services must be FedRAMP authorised + US-region data residency + US citizen personnel access only for FTI + foreign national access requires Office of Safeguards approval. Non-Disclosure Agreements (NDA): all individuals with FTI access must sign NDA per Exhibit 6 + initially + on role change + on renewal of access + post-employment confidentiality obligations + statutory penalties acknowledgement. Disclosure Awareness Training: per Section 9.3.2 + plus Section 9.5 (annual training requirement for all FTI users + role-based + records). Exhibit 7 Contract Language for Contractors: mandatory contract language including (a) FTI access conditions; (b) safeguard requirements; (c) penalties; (d) IRS audit rights; (e) subcontractor consent requirement; (f) termination + return/destruction of FTI; (g) flow-down to subcontractors. Coordinates with NIST SP 800-88 Media Sanitization + NIST SP 800-122 PII Confidentiality + NIST SP 800-171 (Controlled Unclassified Information) + FedRAMP for cloud + FIPS 140-3 Cryptographic Modules + IRC 6103 + 7213 + 7213A + 7431 + Privacy Act + DoD 5220.22-M + DIN 66399. IRS Pub 1075 Section 9.1-9.2 FTI-Specific applies.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.